Not sure how that comment relates to the original question (which was about dynamic IP addresses), but I see a few options to deal with getting multiple matches from your lookup:
This is the dataset that I am currently using
I need to use the dataset for lookup to output the field "siem_severity". The command used are shown below
However, using this command will cause certain events to have two "severity_level" value
I need to find a solution to only display one "severity_level" value.